Pull Findings From Configured API
secobserve_api_importPull vulnerability findings from a configured upstream API into SecObserve, assigning them to a branch and service.
Instructions
Pull findings into SecObserve from an upstream API it already has credentials for.
The credentials, base URL and parser come from an API configuration stored on the product; list them with secobserve_list(resource="api_configurations"). SecObserve fetches and parses inside the request, so the call blocks and can outlast the HTTP timeout. When it does, this returns the state of the work rather than a bare timeout, because the import is still running server-side.
Args: api_configuration_id (Optional[int]) or api_configuration_name (Optional[str]): exactly one. branch_id (Optional[int]) with the id form, or branch_name (Optional[str]) with the name form; a named branch is created if missing. service (Optional[str]): Service to attach findings to. docker_image_name_tag / endpoint_url (Optional[str]): origin metadata.
Returns: str: observations_new, observations_updated and observations_resolved as reported by the API, one per line. On a timeout, a "Still running" text instead: no counts, the secobserve_list call on vulnerability_checks that shows the import landing, and that row's last_import from before the call, which a later value beats.
Examples: - Use when: "refresh findings from our Dependency Track project" -> api_configuration_name="dtrack-portal", branch_name="main" - Use when: scripted re-import after an upstream scan -> api_configuration_id=5 - Don't use when: you have the report file locally (use secobserve_upload_file).
Error Handling: 400 means the upstream call or parse failed -- the message carries the upstream error. A timeout is answered with "Still running" and the query that settles it; never retry on one, since the first import is still going and a second call would run the whole fetch again.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| service | No | Service name to attach the findings to. | |
| branch_id | No | Target branch by id, with the id form. | |
| branch_name | No | Target branch by name, with the name form; created if missing. | |
| endpoint_url | No | Origin metadata: URL. | |
| api_configuration_id | No | Id of the API configuration to pull from. Give this or api_configuration_name. | |
| docker_image_name_tag | No | Origin metadata: image. | |
| api_configuration_name | No | Name of the API configuration to pull from. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |